<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Associates. &#187; security metrics</title>
	<atom:link href="http://www.software.co.il/tag/security-metrics/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il</link>
	<description>Security and compliance specialists for medical device and healthcare companies</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:36:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Data security metrics</title>
		<link>http://www.software.co.il/2009/10/data-security-metrics/</link>
		<comments>http://www.software.co.il/2009/10/data-security-metrics/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 17:47:16 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Data leakage]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Information assurance]]></category>
		<category><![CDATA[security metrics]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2102</guid>
		<description><![CDATA[Anything can be measured. As  Bertrand Russell wrote - All exact science is based on approximation. If a man tells you he knows a thing exactly, then you can be safe in inferring that you are speaking to an inexact man. This is one of the talks I gave at our weekly Thursday seminar &#8211; ...]]></description>
			<content:encoded><![CDATA[<p>Anything can be measured. As  Bertrand Russell wrote -</p>
<blockquote><p>All exact science is based on approximation.  If a man tells you he knows a thing exactly, then you can be safe in inferring that you are speaking to an inexact man.</p></blockquote>
<p>This is one of the talks I gave at our weekly Thursday seminar &#8211; <a title="Data security workshops" href="http://www.controlpolicy.com/workshops" target="_blank">register here for the Webinar</a></p>
<p>The talk discusses how data security metrics can be used in a value-based approach to security, providing examples of security metrics and a number of practical measurement techniques.  The talk also shows how security metrics are used in quantitative risk modeling in order to calculate Value at Risk of information assets and justify security investments by reducing risk at lower costs.</p>
<div id="__ss_2219466" style="width: 425px; text-align: left;"><object style="margin:0px" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=datasecuritymetricsavaluebasedapproach-12555166583093-phpapp01&amp;rel=0&amp;stripped_title=datasecuritymetricsavaluebasedapproach" /><param name="allowfullscreen" value="true" /><embed style="margin:0px" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=datasecuritymetricsavaluebasedapproach-12555166583093-phpapp01&amp;rel=0&amp;stripped_title=datasecuritymetricsavaluebasedapproach" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;"><span id="more-2102"></span></div>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">For more information:</div>
<ul>
<li>The comprehensive source of information security metrics can be found in NIST <a href="http://csrc.nist.gov/publications/nistpubs/800-55/sp800-55.pdf" target="_blank">Special Publication 800-55</a>, <em>“Security Metrics Guide for                      Information Technology Systems”.</em></li>
<li>See Gary Hinson&#8217;s excellent post on <a title="7 myths about security metrics" href="http://www.noticebored.com/html/metrics.html" target="_blank">7 myths about security metrics</a></li>
<li>Andrew Jaquith&#8217;s book Security Metrics &#8211; <em>&#8220;Replacing fear, uncertainty and doubt&#8221;</em></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/10/data-security-metrics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security metrics anti-design patterns</title>
		<link>http://www.software.co.il/2009/04/security-metrics/</link>
		<comments>http://www.software.co.il/2009/04/security-metrics/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 06:41:57 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Anti-Fraud]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Internal security]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Hannaford]]></category>
		<category><![CDATA[IDC]]></category>
		<category><![CDATA[security metrics]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1138</guid>
		<description><![CDATA[I&#8217;ve been thinking recently about how most of our clients don&#8217;t collect security metrics. Then I got thinking about how there are anti-design patterns that typify firms with a higher level of vulnerability to a major data loss event. Running security is not different from running a business &#8211; you have assets and threats, vulnerabilities ...]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.answers.com/topic/anti-design"><img class="alignleft" title="Anti-design patterns" src="http://dominomag.typepad.com/daily__dailydose/images/walteriadog.jpg" alt="" width="181" height="190" /></a></p>
<p>I&#8217;ve been thinking recently about how most of our clients don&#8217;t collect security metrics. Then I got thinking about how there are <strong>anti-design patterns </strong>that typify firms with a higher level of vulnerability to a major data loss event.</p>
<p>Running security is not different from running a business &#8211; you have assets and threats, vulnerabilities and resources to protect the assets. There are widely accepted and practiced revenue models, costing models and performance metrics for businesses of all shapes and sizes, yet information security has not reached this stage of maturity. Taking two security standards as an example (ISO27001/27002 and PCI DSS 1.2) &#8211; it is clear that a well-structured list of security controls is not a substitute for measuring security control effectiveness.</p>
<p>So &#8211; how can we use anti-design patterns for diagnosing a firm with potential security issues?</p>
<p>Let&#8217;s start by looking how a typical business uses metrics.</p>
<p><span id="more-1138"></span></p>
<p>To cost a product or service, a distribution business uses mark up margins, a manufacturing unit uses bill of material costing and a professional services firm uses standard and activity costing. In order to evaluate cash flow, we measure cash flow from operations, or free cash flow (FCF) &#8211; which is cash produced rom operations, less capital expenditures. FCF omits the cost of debt but provides an objective indicator that can be measured every week, every quarter, every month of the year.  We know a major supermarket chain that lost $5M in business to competitors in the holiday season after their purchase prices of fresh produce were leaked to a competitor by an employee. The firm reacted with locked doors and cameras, but locked doors and cameras cannot mitigate the threat of employees with wireless access to Webmail.</p>
<p>Here are 6  <strong>anti-design patterns</strong> that I would propose:</p>
<ul>
<li>Data security spending is driven by privacy regulation</li>
<li>Gartner Group/IDC/Forrester white papers are a key input for information security purchasing</li>
<li>The CSO meets at least 5 new product vendors a month</li>
<li>The purchasing cycle of  new security technology takes 9-15 months (3x slower than the introduction of new security threats)</li>
<li>Cutting back on security head count during restructuring</li>
<li>The CTO never personally sold or installed one of the company&#8217;s products</li>
</ul>
<p>If you answered YES to 4 out of the above 6 anti-design patterns, I would recommend the following:</p>
<ol>
<li>Setup indicators and publish them once a week on the company Intranet for everyone to see. Start with 3 indicators: the number of network anomalies your IDS found that week, your current patch cycle time and how much overtime your security staff worked that week.</li>
<li>Do continuous security audits. Purchase a tool for network audit and run it once a week on a different part of the network. The guys over in the warehouse stopped doing full physical counts once a year 15 years ago, they count a little bit of inventory every day with hand-held barcode terminals. Get a consultant to help you set it up and run it yourself.</li>
<li>Run security awareness programs. Make the number of training hours one of your indicators</li>
<li>Build a threat model and maintain database of your key assets, threats and vulnerabilities and start building a threat model today.</li>
<li>Define your competitive strategy for infosec operations. Is it low cost? Is it single vendor? Is it Linux desktops? Is it end-point security focus?</li>
<li>Think how activities can reinforce each other &#8211; for example by installing personal firewall software that reports on intrusion attempts to a central server so that you can plan your response to future attacks.</li>
<li>Identify sets of activites that optimize your efforts. Perhaps you have a totally flat network with a spagetthi plate of servers and workstations today. Segment the network into VLAN&#8217;s, put the application servers on one segment, the data servers on another and client workstations on departmental segments and so forth. Performance and security will improve and you&#8217;ll be able to monitor content effectively. You&#8217;ll spend less time firefighting and more time thinking.</li>
<li>Install your company&#8217;s products yourself. After you do that, follow a customer home and watch how they do the install, time it and take notes. Update the threat model with your findings.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/04/security-metrics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

